Installation guide
Wireless Guide 149
Advanced Features for Wireless Analysis
Wireless stations exchange Authentication frames with access points to
authenticate themselves with the network, thereby providing security and
privacy. The authentication sequence for 802.11 networks consists of the
exchange of either two authentication frames (for open system authentication)
or four authentication frames (for shared key authentication), each identified
by a transaction sequence number. The extra two authentication frames for
shared key authentication are for the exchange of a string of challenge text,
first sent in the clear by the access point and then returned in encrypted format
by the wireless station.
The Expert generates this alarm when the access point refuses to authenticate
the requesting wireless station. The exact reason for the denial is found in the
Status Code field of the Authentication frame. The Expert reports both the
address of the access point denying the Authentication, as well as the reason
for the denial indicated in the Status Code field.
1 — Unspecified failure.
13 — Responding station does not support the specified authentication
algorithm.
14 — Received an Authentication frame with authentication transaction
sequence number out of expected sequence.
15 — Authentication rejected because of challenge failure.
16 — Authentication rejected due to timeout waiting for next frame in
sequence.
CTS Frame Timeout
The Expert generates the CTS Frame Timeout alarm when it does not see a
clear to send (CTS) frame sent in response to a request to send (RTS) frame
within the time specified in the Duration field of the original RTS frame.
RTS frames include a Duration field indicating the amount of time within which
a receiving station should return a CTS frame. The value of this field is typically
equal to the amount of time required to send the CTS frame, one ACK frame,
and three short interframe spaces (SIFS). The Duration field lets other stations
on the network know that during this period, the medium is reserved.
When the Expert sees an RTS frame, it stores the value specified in the
Duration field in a buffer. If it does not see the corresponding CTS frame within
the value specified by the Duration field, it generates this alarm.